Simulated workplaceCAQA Nova Digital Systems is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
ICTCAQA NovaSimulated workplace
Back to library
CAQA Nova Digital Systems · Simulated workplace

Disaster Recovery and Business Continuity Plan

PlanControlled document
NOV-PLN-050
v3.0
Document ownerNetwork and Infrastructure Manager
Version3.0
Approved16 June 2026
Next review16 June 2027
StatusCurrent

Purpose. This plan sets out how Nova keeps its own operations running and restores client systems after a major outage, cyber attack or loss of a site.

1.Scope and objectives

This plan covers loss of the Richmond network operations centre, loss of a core platform such as ticketing or the password vault, a ransomware event affecting Nova or a client, and a widespread cloud provider outage. The objective is to restore the service desk within two hours and tier one client systems within their agreed recovery time.

2.Roles

The Chief Executive Officer declares a disaster and leads communication. The Network and Infrastructure Manager leads technical recovery. The Cyber Security Lead leads containment where the cause is an attack. The Service Desk Manager runs client communication and the Business Services Manager handles staff, suppliers and insurers.

3.Nova platforms

Nova's core platforms are cloud hosted with a secondary region and are backed up under the Backup and Restore Procedure. The password vault has an offline emergency copy held by two executives. Staff can work from any office or home with their laptops, and the service desk phone system can be redirected within 30 minutes.

  • Ticketing, documentation and monitoring in cloud with secondary region
  • Offline emergency vault copy held by two executives
  • Service desk phones redirect within 30 minutes
  • Staff laptops enable work from any location

4.Client recovery priorities

Each client system carries a disaster recovery tier in its site documentation. Tier one systems will be restored within four hours, tier two within 24 hours and tier three within 72 hours. Where many clients are affected at once, medical, community services and school clients will be restored first.

5.Ransomware response

Affected systems will be isolated, immutable backups verified and restored to clean infrastructure, and credentials rotated before reconnecting. No ransom will be paid without a decision by the Chief Executive Officer with legal advice and the client's agreement.

6.Communication

Clients will receive an initial notice within one hour of a declared disaster and updates every two hours until service is restored. Staff will be contacted through the emergency messaging list.

7.Testing and review

A desktop exercise will be held every six months and a full failover test of the core platforms annually. The plan will be updated after every test and every real activation.

NOV-PLN-050 v3.0 · CAQA Nova Digital SystemsUncontrolled when printed. Simulated document created by CAQA for training and assessment.

Related documents

  • None